
Security News
Open VSX Unblocks Extension IDs Used in Malware Campaign
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.
geoaeo makes any app discoverable, quotable, and usable by AI answer engines and search —
SEO, GEO, and AEO in one tool. It audits a site, scores it 0–100, and generates the files
answer engines need. It ships a library, a CLI, and an MCP server, all at one version.
npm install geoaeo
The package name is unscoped: geoaeo, geoaeo (CLI), and geoaeo-mcp (MCP server).
Create geoaeo.config.ts from geoaeo.config.example.ts.
The config holds the site facts used by every generator.
Audit a live site:
npx geoaeo audit https://example.com
npx geoaeo audit https://example.com --json
Audit a local build or source directory:
npx geoaeo audit ./apps/website
Scaffold a Next.js App Router site:
npx geoaeo init ./apps/website
npx geoaeo init ./apps/website --force
The command detects the framework — Next.js, Astro, SvelteKit, Nuxt, or Remix — and writes
the routes that emit each artifact. Other directories receive static files. Existing files
stay unchanged unless you pass --force.
npx geoaeo gen llms
npx geoaeo gen llms-full --output public/llms-full.txt
npx geoaeo gen jsonld --type faq
npx geoaeo gen webmcp
npx geoaeo gen sitemap --output public/sitemap.xml
npx geoaeo gen robots
npx geoaeo gen ogimage --output public/og.svg
npx geoaeo gen rss --output public/feed.xml
npx geoaeo gen hreflang
npx geoaeo gen mdmirror
The generators use the same config as the generated framework routes.
The JSON-LD generator supports software, product, faq, breadcrumb, organization,
website, article, howto, person, and review kinds.
Use --ci in a pipeline to fail when a site drops below a minimum score:
npx geoaeo audit https://example.com --ci --min-score 85
The command exits non-zero when the score is below the threshold.
Run a report for Markdown and JSX files:
npx geoaeo humanize 'content/**/*.md' --check
Rewrite prose in place:
npx geoaeo humanize 'src/**/*.tsx' --write
The humanizer keeps YAML frontmatter, code fences, JSX tags, imports, class names, and expressions. It checks for em dashes, AI vocabulary, filler, hype, fake-depth tails, and title-case headings.
Use the stdio server in an MCP client such as Claude Code or Cursor:
{
"mcpServers": {
"geoaeo": {
"command": "npx",
"args": ["geoaeo-mcp"]
}
}
}
The server exposes audit, gen, and humanize tools.
You can also run it through the CLI:
npx geoaeo mcp
| Command | Purpose |
|---|---|
audit <url-or-dir> | Score the site and list missing artifacts. |
init [dir] | Add Next.js routes or static artifacts. |
gen <artifact> | Print one generated artifact or write it to a file. |
humanize <glob> | Check or rewrite prose files. |
mcp | Run the MCP server over stdio. |
npm test
npm run typecheck
npm run build
FAQs
GEO and AEO artifacts for answer engines and agents
The npm package geoaeo receives a total of 55 weekly downloads. As such, geoaeo popularity was classified as not popular.
We found that geoaeo demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.

Product
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.

Product
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.